Live data from Hacker News

$15 Dedicated servers from OVH

ruchirablog.com

121–130 of 133 posts

Re: $15 Dedicated servers from OVH

#121

Earlier quoted context omitted.

But a bug in a web-server running as root might lead to privileged execution of arbitrary code. It's certainly true that a bug in the authentication code that incorrectly grants access is of substantially less severity than a leak or abuse of root key/password.

Obviously you have to compare the likelihood of remote code execution in nginx/apache to that of ssh. Nginx is much, much simpler than OpenSSH. And, obviously, giving a third party remote root SSH access to your server already is a glaring vulnerability .

The nginx package on Debian has more LOC than the openssh-server package. Apache, of course, is huge. This doesn't map perfectly onto complexity, but gives some indication that "much, much simpler" may not be entirely accurate.

Moreover, the default SSH setup gives you everything you need for the (still undesirable) current setup, and is almost certainly running regardless. The default nginx install does not - you have to tweak setup to lock it down and add stuff to actually fetch the content, and since that (we have stipulated) has to be done as a privileged user there is room for error.

Again, giving a root login key to OVH means no security against OVH, and relying on their securing the key. I agree that this is a bad idea. Depending on the amount you trust OVH and their security, it may be more secure against people other than OVH than certain specific alternatives (perhaps all the alternatives if you artificially constrain yourself into running a single process as root that talks to the outside).

Re: $15 Dedicated servers from OVH

#122
post #40

I'm french and I've been using low-cost offers from OVH (Kimsufi) or Illiad (Online.net) since a couple of years. I just have ONE objection: If you plan to do something professional with them, just, don't. For them, every client is dispensable (even if you rent 200 servers or more). They won't hesitate a single second to delete your server if they have a small problem with you (for example, getting DDoS'd). OVH have…

Just another proof: they recently removed the possibility to rent RIPE IPs with a Kimsufi offer.

I choosed Kimsufi because of the possibility to rent RIPE IPs… they removed the possibility without telling anybody…

Re: $15 Dedicated servers from OVH

#123

Earlier quoted context omitted.

Obviously you have to compare the likelihood of remote code execution in nginx/apache to that of ssh. Nginx is much, much simpler than OpenSSH. And, obviously, giving a third party remote root SSH access to your server already is a glaring vulnerability .

The nginx package on Debian has more LOC than the openssh-server package. Apache, of course, is huge. This doesn't map perfectly onto complexity, but gives some indication that "much, much simpler" may not be entirely accurate. Moreover, the default SSH setup gives you everything you need for the (still undesirable) current setup, and is almost certainly running regardless. The default nginx install does not - you ha…

Nginx is much, much simpler than OpenSSH.

Re: $15 Dedicated servers from OVH

#124

Earlier quoted context omitted.

The nginx package on Debian has more LOC than the openssh-server package. Apache, of course, is huge. This doesn't map perfectly onto complexity, but gives some indication that "much, much simpler" may not be entirely accurate. Moreover, the default SSH setup gives you everything you need for the (still undesirable) current setup, and is almost certainly running regardless. The default nginx install does not - you ha…

Nginx is much, much simpler than OpenSSH.

This seems an absurd digression.

"Simpler" is surely something we could quantify, and while LOC tracks it loosely it's obviously not the same thing, and SSH is almost certainly more complex per LOC than typical. Where that becomes "much" simpler, and from there "much, much" simpler is fundamentally subjective, but if you want to put up some numbers based on some other metric feel free, and we can take this further; it strikes me as unlikely that a smaller system would fall in the range I would label "much, much simpler" - but I am not an expert on either piece of software.

Regardless, it is a digression. The complexity of openssh is not at issue, unless you are advocating they not use openssh at all. Nginx + openssh is absolutely unequivocally not "much, much simpler" than openssh.

Adding nginx interfacing with new, privileged code does add significant complexity that using-the-already-present-ssh does not. Some of this complexity is exposed to those who do not have any credentials. Therefore, the security of the system toward those attackers may go up for those reasons more than it goes down because of the existence of an additional set of root credentials they do not have easy access to. This is presuming that OVH's security is sufficiently trusted; a big assumption, to be sure.

We're still agreed that the best approach is some kind of reasonable hand-off of data from the privileged process that reads the data and the external access of whatever form, presuming any of the data really needs privileged access in the first place.

Re: $15 Dedicated servers from OVH

#125

Earlier quoted context omitted.

Nginx is much, much simpler than OpenSSH.

This seems an absurd digression. "Simpler" is surely something we could quantify, and while LOC tracks it loosely it's obviously not the same thing, and SSH is almost certainly more complex per LOC than typical. Where that becomes "much" simpler, and from there "much, much" simpler is fundamentally subjective, but if you want to put up some numbers based on some other metric feel free, and we can take this further; i…

The reasoning you're using here about exposed attack surface and complexity is faulty. You are better off exposing a trivial interface with nginx or Apache than in giving someone SSH credentials.

Re: $15 Dedicated servers from OVH

#126

Earlier quoted context omitted.

This seems an absurd digression. "Simpler" is surely something we could quantify, and while LOC tracks it loosely it's obviously not the same thing, and SSH is almost certainly more complex per LOC than typical. Where that becomes "much" simpler, and from there "much, much" simpler is fundamentally subjective, but if you want to put up some numbers based on some other metric feel free, and we can take this further; i…

The reasoning you're using here about exposed attack surface and complexity is faulty. You are better off exposing a trivial interface with nginx or Apache than in giving someone SSH credentials.

> The reasoning you're using here about exposed attack surface and complexity is faulty.

Could you point to the fault?

Re: $15 Dedicated servers from OVH

#127

Earlier quoted context omitted.

The reasoning you're using here about exposed attack surface and complexity is faulty. You are better off exposing a trivial interface with nginx or Apache than in giving someone SSH credentials.

> The reasoning you're using here about exposed attack surface and complexity is faulty. Could you point to the fault?

I could, easily, but we're pretty far to the right margin. If you'd like to email me, I'm happy to explain the reasoning.

Re: $15 Dedicated servers from OVH

#128
post #80

I hope 2013 brings $99 dedicated with hardware raid (you can pay that for software raid now). But atom for a server? Yuck. I'd rather have a real server cpu under virtual xen instead.

You must be doing some task that I've never used my servers for if you consider a dedicated Atom somehow vastly inferior to a virtualized "real CPU". My servers are never CPU bound. They are disk, memory, and I/O bound, in that order. I couldn't possibly overwork the CPU on any machine I have...web service is simply not a CPU-intensive task. Besides that, Atom CPUs are quite fast for many kinds of tasks...sometimes f…

A cpu less at load is a far more responsive cpu.

Atom was designed to be crippled from the start to save power.

You must be running smaller, single site servers, possibly with mostly static content?

I am willing to bet atom would choke on non-indexed searches, compression/decompression and encryption.

The Intel (and now AMD) aes in hardware acceleration for ssl is worth it alone on a real cpu vs atom.

Re: $15 Dedicated servers from OVH

#129

I use OVH for a rutorrent and PLEX server. I have the 8G one for 40 bucks a month. It is the seedbox for six users and runs PLEX so everyone can stream to their phones or computer or AppleTV. It has mostly replaced cable tv for everyone that uses it.

This is what I was curious about. You dont have any problems running ruTorrent through them?

Re: $15 Dedicated servers from OVH

#130
post #76
post #10

And just in case somebody isn't comfortable using the french website, the irish one has the same offers: http://www.ovh.ie/dedicated_servers/kimsufi.xml (the german one is strangely enough more expensive)

Their prices do seem to bounce around a bit, even for countries that use the same currency. There's an issue in that (as I understand it) in Germany you have a quote VAT inclusive prices but in Ireland you can leave off VAT for goods aimed at businesses. (The same is true in the UK). Even taking that into account there's about a 20% price bump from Ireland to Germany, though!

If you buy as a company Germany actually seems to be the cheapest as you don't have to consider VAT in any countries. Or am I missing something?
Post reply on HN